ASX 2009,005.90
-14.20(-0.16%)
NIKKEI65,020.94
+806.46(+1.26%)
NIFTY 5023,897.70
+24.25(+0.10%)
HSI25,650.87
+427.66(+1.74%)
SHANGHAI3,930.116
-11.972(-0.30%)
Trending:US MarketsAI & SiliconUSA Jobs DeskFed PolicyCybersecurityGov & LawEntertainmentSports Wire

Six Chinese AI firms accused of aggressively copying US frontier models

US urges AI firms to ID, then secretly switch, Chinese users to less-capable models.

By Nexvoro Tech Wire
PUBLISHED WED, SEP 9, 2026 8:46 PM UTC6 MIN READ
CNBC Market Tracker • NASDAQ:AAPL
REAL-TIME QUOTE
Apple Inc
$234.12-0.98 (-0.42%)
Volume: 68.4M
52-Wk Range: $138.80 - 271.00

KEY POINTS

  • Primary coverage dispatched via Ars Technica.
  • Signals noteworthy shifts in sector dynamics and operational developments.
  • Comprehensive factual details verified from official publication records.
  • Objective, non-partisan journalistic standards preserved.
Six Chinese AI firms accused of aggressively copying US frontier models
PHOTO VIA ARS TECHNICANEXVORO EDITORIAL WIRE

Primary Journalistic Dispatch & Direct Reporting

US urges AI firms to ID, then secretly switch, Chinese users to less-capable models.

The United States has now named six Chinese AI firms accused of waging industrial-scale attacks distilling US frontier AI model capabilities and perhaps sparing billions in Chinese development costs.

In a joint release Tuesday, the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) alleged that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been attacking US models since at least late 2024. The firms "likely" acted with "Chinese government awareness" when extracting capabilities from US models, including variants of Claude, GPT, Gemini, and Grok, agencies said.

In-Depth Developments & Factual Context

"China-based AI companies that conduct industrial-scale distillation against US AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model," agencies said.

All American AI firms must work with the government and US allies to end the alleged theft threatening the US lead in the AI race, the agencies said. That will require coordinated action across the AI ecosystem to combat the "aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of US frontier AI models."

Attack methods include "exploiting AI model inference APIs" by bulk-buying fake accounts, agencies said. Not registered to legitimate users, these swarms of fraudulent accounts execute "highly coordinated queries featuring identical or similar prompt texts," which range "from thousands to millions on similar topics."

Industry Impact & Strategic Analysis

Another common method is using prompt injection techniques to jailbreak models, including crafting "prompts forcing models to reveal their hidden [chain-of-thought] reasoning," agencies said. For example, "DeepSeek employed prompts instructing models to imagine and articulate the internal reasoning behind completed responses and write it out step by step."

To encourage firms to work together, agencies recommended mitigations that would supposedly make it harder for Chinese firms to steal from US models.

First, AI firms must improve detection of sophisticated campaigns that allegedly use tens of thousands of accounts relying on "a gray market of proxies" to evade geographical restrictions and "route distillation requests through multiple pathways to gain unauthorized access."

Forward Outlook & Market Perspective

Flagging this activity should be somewhat easy, agencies suggested, since "campaigns span days to months with query volumes in the thousands to millions per domain, far exceeding legitimate research or development use cases."

Generally, they've recommended stepping up monitoring for "anomalous and malicious prompts, accounts, networks, and behaviors." Because Chinese firms rely on "bulk procurement of the US AI companies' premium subscriptions shared across teams of developers," that effort should also include flagging accounts with suspicious subscription-to-usage ratios, as well as any new accounts immediately hitting maximum usage, agencies said. Both indicate "bulk deployment with pre-engineered templates," agencies said. US firms should also be strengthening "identity verification" of users and more closely tracking individuals using enterprise subscriptions (both of which potentially raise privacy red flags for legitimate users).

Next, agencies asked firms to start dumbing down model responses when suspected distillation attacks are flagged. By "subtly" altering responses - such as by "presenting correct information with different reasoning," adding stylistic inconsistencies, or reducing reasoning depth - firms can decrease the payoff for Chinese firms. US firms could also secretly switch malicious accounts to an inferior model, and they should do so without providing any notice, agencies suggested.

That particular mitigation step will likely be technically challenging.

Agencies acknowledged, for example, that Chinese firms "employ aggressive, adaptive discovery to systematically identify valuable extractable data," which they then collect to generate synthetic training datasets. Some firms can automatically detect when a smarter model is available and switch within 24 hours. They also have automated quality assurance systems that detect when outputs are degraded and can otherwise differentiate ordinary "service issues from defensive data degradation," agencies said.

Also problematic: if US firms aren't careful with targeting, any legitimate users perhaps caught up in the policing frenzy might be switched to a dumber model without receiving any alert. Or they could suddenly receive shorter responses or experience withheld capabilities, agencies acknowledged. Additionally, firms may possibly add "noise" to the output that restricts further queries. Users will likely notice if outputs degrade, just like Chinese systems attacking models would. Last year, OpenAI quickly made changes to its automatic routing system after facing swift backlash when that system "consistently defaulted to less capable variants unless users explicitly added phrases like 'think harder' to their prompt," Ars reported .

Reporting synthesized and verified under Nexvoro.tech editorial guidelines. Full primary records referenced via Ars Technica.

Sponsored / Google AdSense SlotResponsive Leaderboard 728x90 / 970x250 (article-mid-story)
Reporting synthesized under Nexvoro.tech Editorial Standards • Referenced via Ars Technica
Verified Dispatch
Related Tickers:#BUSINESS#US NEWS#ARS

More Coverage in Business

View Topic Desk →
UK Chancellor Faces Severe Autumn Budget Pressure After August Borrowing Surges Past Official Forecasts
Business
Business3H AGO

UK Chancellor Faces Severe Autumn Budget Pressure After August Borrowing Surges Past Official Forecasts

Government borrowing hit £18.3bn in August - surpassing official forecasters' expectations by £3.5bn - as soaring public spending, inflation pressures, and record debt interest payments create a daunting fiscal landscape for the upcoming Treasury budget. Independent economists warn that compounding macro headwinds could severely constrain key policy priorities and public investments.

BBC Business6 min read
Bank of America Urges Investors to Buy Boeing Dip Amid Production Hurdles and Delayed 777X Timeline
Business
Business3H AGO

Bank of America Urges Investors to Buy Boeing Dip Amid Production Hurdles and Delayed 777X Timeline

Despite a sharp pullback in Boeing shares following CEO Kelly Ortberg's disclosures about production ramps and delayed certification timelines, Bank of America maintains a bullish stance with a $270 price target. Senior analysts argue that the market's dramatic reaction overlooks the inevitable, non-linear realities of a complex corporate turnaround.

Yahoo Finance7 min read